GitHubã®ãçºãã¦ããããORYã®oathkeeperãè¦ã¤ãã
ãããGoogleã社å
ã§ä½¿ç¨ãã¦ãããBeyondCorpããåèã«ãã¦ããã¨ãããã¨ãæ¸ãã¦ãã£ãã®ã§ããã®è«æãèªãã ã
BeyondCorpã¨ã¯
GoogleãVPNã®ä»£ããã«ä½¿ç¨ãã¦ãããèªè¨¼ã»èªå¯ã®ã·ã¹ãã ã
人ã»ããã¤ã¹ã»ãããã¯ã¼ã¯ãªã©ãåºã«ç¤¾å
ã·ã¹ãã ã¸ã®ã¢ã¯ã»ã¹å¶å¾¡ãè¡ããããã«ãã«ãã§ãªã©ãããGoogle社å
ã·ã¹ãã ã¸ã®ã¢ã¯ã»ã¹ãã§ããããã«ãªã£ã¦ããã
è«æã¯ä½åãåºããã¦ããããèªãã ã®ã¯ãBeyondCorp: A New Approach to Enterprise Security
ã¾ããGCPã®ãµã¼ãã¹ã«ããªã£ã¦ãã¦ãCloud Identity-Aware proxyã¨ããååã«ãªã£ã¦ãã
BeyondCorpã®ä»çµã¿
å³ã«ããã¨ãâã®ãããªæ§æããã
èªè¨¼
HRã®ã·ã¹ãã ã¨çµã³ã¤ãã¦ã·ã³ã°ã«ãµã¤ã³ãªã³ããã£ã¦ããã¨æ¸ãã¦ããããå
·ä½çã«ã¯ãã¾ãæ¸ãã¦ããªãã
Cloud Identity-Aware proxyã§ã¯ãã»ãã¥ãªãã£ãã¼ã¨ããããã¤ã¹ã使ã£ã¦äºè¦ç´ èªè¨¼ããã¦ããã®ã§ãåããããªãã®ãããã¯ãã (https://login.corp.google.com/?gnubby=0 ãè¦ã¦ããSecurityKeyã®è¨è¼ããã)
èªå¯
権éå¶å¾¡ã®ã·ã¹ãã ã¯ãAccessControlEngineã¨ããååãã¤ãã¦ãã¦ã
- ã¦ã¼ã¶ã¼
- ã¦ã¼ã¶ã¼ã®æå±ããçµç¹
- ããã¤ã¹
- å ´æ
ãåºã«æ¨©éãä¸ãã¦ããã
ä¾ãã°ããã°ãã©ãã«ã¼ã使ããã®ã¯ããã«ã¿ã¤ã éçºè
ãéçºãã·ã³ããè¦ã¦ããæã ãã財åã·ã¹ãã ã¯ãã¡ã¤ãã³ã¹ã°ã«ã¼ãã®ãã«ã¿ã¤ã ããã¼ãã¿ã¤ã ã ãããªã©ãåãããã¦ããã
権éå¶å¾¡ã¯ãµã¼ãã¹åä½ã ãã§ãªãããµã¼ãã¹ã®è¦ç´ ã«å¯¾ãã¦ãå²ãå½ã¦ãããããã°ãã©ãã«ã¼ã®ãã°è©³ç´°ã®ãã¼ã¸ãè¦ã権éã¨ãæ¤ç´¢ãæ´æ°ãã権éã¯å¥ã«ãããã¨ãåºæ¥ããããã
ã¾ããGoogleã®ãã«å
ããã®ã¢ã¯ã»ã¹ãã©ããã¨ããæ°ããå ´æããã®ã¢ã¯ã»ã¹ãã§èªè¨¼ã¬ãã«ãå¤ãã¦ããããOSã®ããããããã£ã¦ãããã©ããã§ãå¤ãã¦ãããããã
ä»
VPNãããBeyondCorpã¸ç§»è¡ããã®ã¯å¤§å¤ã ã£ãããã§ãå¾åã¯ããã«ã¤ãã¦æ¸ãã¦ããã
ãã¨ãå社å
ãµã¼ãã¹ã¸ã®å
¥ãå£ã¸ã®FQDNã¯DNSã§å
¬éãã¦ããã¨æ¸ãã¦ãããããã¯ã社å¤ãããã¯ã¼ã¯ã使ã£ã¦ãã以ä¸ãå¿
è¦ã ããã¨ããæãããµã¼ãã¹æ¬ä½ã®æ
å ±ã¯ç¤¾å
DNSããå¼ããã®ãããããªãã